← Back to events
ResolvedTechRelease26.5.1

2026-07-29, Version 26.5.1 (Current), @RafaelGSS

Photo: Node.js Releases

What happened

This is a security release. Notable Changes ( CVE-2026-56848 ) http2: defer rst stream while in scope (Matteo Collina) – High ( CVE-2026-58043 ) permission: avoid granting radix split nodes (RafaelGSS) – High ( CVE-2026-56850 ) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium ( CVE-2026-58040 ) https: bind identity checks to session reuse (Matteo Collina) – Medium ( CVE-2026-58041 ) sqlite: invali…

Summary assembled by rule from the sources below

Why it's spreading

Sources